<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you Jon, I will Do that in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676597#M194314</link>
    <description>&lt;P&gt;Thank you Jon, I will Do that.&lt;/P&gt;&lt;P&gt;Ejaz&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jun 2015 12:09:25 GMT</pubDate>
    <dc:creator>Ejaz Ahmed</dc:creator>
    <dc:date>2015-06-26T12:09:25Z</dc:date>
    <item>
      <title>NAT Issue ASA 9.1</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676593#M194306</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;Please help me on this, I have upgraded my cisco asa from 8.2 to 9.1 version. I know that cisco made huge changes in NAT configuration. The firewall 8.2 is configured with lots&amp;nbsp; static PAT and dynamic PAT lines. Now I am going to convert these lines to 9.1 format. I have successfully configured the static PAT line, which mainly doing the port forward (ie same port number on external and internal). But i got stuck in port redirection, it is not working for me. Please see the following lines that I configured my firewall&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1.&amp;nbsp; RDP connection to one of the internal machine&amp;nbsp; from external&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Object network Obj_RDP_192.168.1.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;host 192.168.1.10&lt;BR /&gt;nat (inside, outside) static x.x.x.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outside_inside extended permit tcp any host 192.168.1.10 eq 3389&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The above lines are working for me. I can RDP to the machine 192.168.1.10 from external using the public IP x.x.x.x&lt;/P&gt;&lt;P&gt;Now see the below command which is not working for me:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. RDP to another internal machine&amp;nbsp; (Since the port 3389 already used for the first machine, I selected port 2000 here)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Object network Obj_RDP_192.168.1.11&lt;BR /&gt;1host 192.168.1.11&lt;BR /&gt;nat (inside, outside) static x.x.x.x service tcp 3389 2000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list outside_inside extended permit tcp any host 192.168.1.11 eq 2000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please provide me a solution for the 2nd configuration line.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ejaz&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676593#M194306</guid>
      <dc:creator>Ejaz Ahmed</dc:creator>
      <dc:date>2019-03-12T06:11:09Z</dc:date>
    </item>
    <item>
      <title>EjazRDP to another internal</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676594#M194308</link>
      <description>&lt;P&gt;Ejaz&lt;/P&gt;&lt;P&gt;&lt;EM&gt;RDP to another internal machine&amp;nbsp; (Since the port 3389 already used for the first machine, I selected port 2000 here)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I don't understand what you mean here. You are using a different public IP ie. y.y.y.y so why do you need to use a different port number ?&lt;/P&gt;&lt;P&gt;I am assuming y.y.y.y is another of your public IPs and part of the same IP subnet as x.x.x.x ?&lt;/P&gt;&lt;P&gt;That aside can you run -&lt;/P&gt;&lt;P&gt;"packet-tracer input outside tcp 8.8.8.8 12345 y.y.y.y 2000"&lt;/P&gt;&lt;P&gt;and post results.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 11:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676594#M194308</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-06-26T11:40:33Z</dc:date>
    </item>
    <item>
      <title>Thanks for the response Jon.,</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676595#M194310</link>
      <description>&lt;P&gt;Thanks for the response Jon., Sorry my bad its same public IP. We have only one static public which is configured in firewall's WAN interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Ejaz&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 11:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676595#M194310</guid>
      <dc:creator>Ejaz Ahmed</dc:creator>
      <dc:date>2015-06-26T11:52:01Z</dc:date>
    </item>
    <item>
      <title>EjazOkay, that's the problem</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676596#M194312</link>
      <description>&lt;P&gt;Ejaz&lt;/P&gt;&lt;P&gt;Okay, that's the problem.&lt;/P&gt;&lt;P&gt;Your first statement is a one to one mapping ie. it uses all ports so it never hits your second statement.&lt;/P&gt;&lt;P&gt;You need to rewrite your first statement to be a static PAT statement ie. like your second one but you can use port 3389 with the first statement, no need to translate the port.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 11:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676596#M194312</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-06-26T11:55:23Z</dc:date>
    </item>
    <item>
      <title>Thank you Jon, I will Do that</title>
      <link>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676597#M194314</link>
      <description>&lt;P&gt;Thank you Jon, I will Do that.&lt;/P&gt;&lt;P&gt;Ejaz&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 12:09:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-issue-asa-9-1/m-p/2676597#M194314</guid>
      <dc:creator>Ejaz Ahmed</dc:creator>
      <dc:date>2015-06-26T12:09:25Z</dc:date>
    </item>
  </channel>
</rss>

